app: every process the engine starts on Windows is hidden (platform::quiet on the window host, icacls, reg, the setup's cmd; igneum-prove-verify is a windows-subsystem exe, the node starts it with no console of its own)

The four helpers (detect::run_timeout, jobrun::run_capture, jobrun::run_streamed, procs::spawn) already set
CREATE_NO_WINDOW; the direct .output()/.spawn() sites did not. 5 October 2026: a console window on both PCs.
This commit is contained in:
igneum-labs 2026-10-05 08:39:49 +00:00
parent 0f6fc2ead5
commit 545bdb2f0e
5 changed files with 14 additions and 6 deletions

View file

@ -12,6 +12,12 @@
//!
//! Exit 2 is reserved for "no host": the engine probes before it sets the variable, so a node never gets a
//! verifier that cannot run. The wrapper never trusts a proof it did not verify.
//!
//! No console of its own on Windows: the node that starts it has none (the engine starts igneumd with
//! CREATE_NO_WINDOW), so a console-subsystem wrapper would open a visible window on every verification
//! (5 October 2026: a console window on both PCs). Piped stdout and the exit code still reach the caller.
#![cfg_attr(windows, windows_subsystem = "windows")]
#[path = "../wslhost.rs"]
mod wslhost;

View file

@ -56,6 +56,7 @@ fn main() {
if host.exists() {
let mut c = std::process::Command::new(&host);
c.current_dir(&dir);
crate::platform::quiet(&mut c); // no console of our own for the window host (it is a GUI program; the flag only governs a console)
if c.spawn().is_ok() {
return;
}

View file

@ -1107,7 +1107,7 @@ fn stage(e: &PlatformEntry, file: &Path, dir: &Path, version: &str) -> Result<Pa
if again != e.sha256 {
return Err("the download changed while it was being unpacked; discarded".into());
}
let _ = Command::new(crate::platform::tool("xattr")).args(["-dr", "com.apple.quarantine"]).arg(&staged).output();
let _ = crate::platform::quiet(&mut Command::new(crate::platform::tool("xattr"))).args(["-dr", "com.apple.quarantine"]).arg(&staged).output();
let v = crate::detect::run_timeout(Command::new(staged.join("Contents/MacOS/igneum-app")).arg("--version"), None, Duration::from_secs(20)).unwrap_or_default();
let want = format!("igneum-app {version}");
if v.trim() != want {
@ -1116,7 +1116,7 @@ fn stage(e: &PlatformEntry, file: &Path, dir: &Path, version: &str) -> Result<Pa
Ok(())
})();
if let Some(m) = mounted {
let _ = Command::new(crate::platform::tool("hdiutil")).args(["detach", "-force", &m.display().to_string()]).output();
let _ = crate::platform::quiet(&mut Command::new(crate::platform::tool("hdiutil"))).args(["detach", "-force", &m.display().to_string()]).output();
}
let _ = std::fs::remove_dir_all(&work);
if let Err(err) = r {

View file

@ -169,7 +169,7 @@ pub fn lock_permissions(path: &Path, dir: bool) {
let _ = dir;
let user = std::env::var("USERNAME").unwrap_or_default();
if !user.is_empty() {
let _ = Command::new(tool("icacls"))
let _ = quiet(&mut Command::new(tool("icacls")))
.arg(path)
.args(["/inheritance:r", "/grant:r", &format!("{user}:F")])
.output();
@ -314,9 +314,9 @@ pub fn set_start_at_login(on: bool) -> Result<(), String> {
let key = r"HKCU\Software\Microsoft\Windows\CurrentVersion\Run";
let out = if on {
let cmd = login_command().iter().map(|a| format!("\"{a}\"")).collect::<Vec<_>>().join(" ");
Command::new(tool("reg")).args(["add", key, "/v", "Igneum Miner", "/t", "REG_SZ", "/d", &cmd, "/f"]).output()
quiet(&mut Command::new(tool("reg"))).args(["add", key, "/v", "Igneum Miner", "/t", "REG_SZ", "/d", &cmd, "/f"]).output()
} else {
Command::new(tool("reg")).args(["delete", key, "/v", "Igneum Miner", "/f"]).output()
quiet(&mut Command::new(tool("reg"))).args(["delete", key, "/v", "Igneum Miner", "/f"]).output()
};
match out {
Ok(o) if o.status.success() || !on => Ok(()),
@ -338,7 +338,7 @@ pub fn start_at_login_is_on() -> bool {
}
#[cfg(windows)]
{
Command::new(tool("reg"))
quiet(&mut Command::new(tool("reg")))
.args(["query", r"HKCU\Software\Microsoft\Windows\CurrentVersion\Run", "/v", "Igneum Miner"])
.output()
.map(|o| o.status.success())

View file

@ -515,6 +515,7 @@ pub fn setup(shared: &Shared) -> Result<Value, String> {
let line = format!("bash {}", wsl_path(&script));
let mut c = Command::new(crate::platform::tool("cmd"));
c.args(["/c", "start", "", &crate::platform::tool("wsl").display().to_string(), "-d", crate::wslhost::DISTRO, "--", "bash", "-lc", &line]);
crate::platform::quiet(&mut c); // cmd itself hidden; `start` still opens the setup's own window
c.spawn().map_err(|e| e.to_string())?;
shared.event("proving", "WSL2 prover setup started in its own window");
Ok(json!({ "ok": true }))